CVE Feed

    Dashboard / CVE / CVE-2023-35802

    CVE-2023-35802

    IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.

    Published:Jul 15, 2023
    Last Modified:Nov 21, 2024
    EPS:Jul 15, 2023
    EPSS Score:0.02771
    CVSS Score:9.8

    Affected Products

    Vendor
    Extremenetworks
    Product
    Ap1130
    Vendor
    Extremenetworks
    Product
    Ap122
    Vendor
    Extremenetworks
    Product
    Ap130
    Vendor
    Extremenetworks
    Product
    Ap150w
    Vendor
    Extremenetworks
    Product
    Ap250
    Vendor
    Extremenetworks
    Product
    Ap30
    Vendor
    Extremenetworks
    Product
    Ap3000
    Vendor
    Extremenetworks
    Product
    Ap3000x
    Vendor
    Extremenetworks
    Product
    Ap302w
    Vendor
    Extremenetworks
    Product
    Ap305c
    Vendor
    Extremenetworks
    Product
    Ap305c-1
    Vendor
    Extremenetworks
    Product
    Ap305cx
    Vendor
    Extremenetworks
    Product
    Ap4000
    Vendor
    Extremenetworks
    Product
    Ap4000-1
    Vendor
    Extremenetworks
    Product
    Ap410c
    Vendor
    Extremenetworks
    Product
    Ap410c-1
    Vendor
    Extremenetworks
    Product
    Ap460c
    Vendor
    Extremenetworks
    Product
    Ap460s12c
    Vendor
    Extremenetworks
    Product
    Ap460s6c
    Vendor
    Extremenetworks
    Product
    Ap5010
    Vendor
    Extremenetworks
    Product
    Ap5050d
    Vendor
    Extremenetworks
    Product
    Ap5050u
    Vendor
    Extremenetworks
    Product
    Ap510c
    Vendor
    Extremenetworks
    Product
    Ap510cx
    Vendor
    Extremenetworks
    Product
    Ap550
    Vendor
    Extremenetworks
    Product
    Ap630
    Vendor
    Extremenetworks
    Product
    Ap650
    Vendor
    Extremenetworks
    Product
    Ap650x
    Vendor
    Extremenetworks
    Product
    Iq Engine

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High